{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,15]],"date-time":"2025-08-15T01:08:25Z","timestamp":1755220105272,"version":"3.43.0"},"reference-count":79,"publisher":"Association for Computing Machinery (ACM)","issue":"7","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Knowl. Discov. Data"],"published-print":{"date-parts":[[2025,8,31]]},"abstract":"<jats:p>It has been shown that deep recommendation models are susceptible to adversarial attacks, with this vulnerability potentially leading to significant economic losses in the e-commerce field. However, the robustness of deep recommendation models in response to adversarial attacks has not been systematically investigated. In this article, therefore, we comprehensively evaluate the adversarial robustness of various representative deep models in different settings, aiming to analyze their performance impact under adversarial attacks and compare it with traditional collaborative filtering models. Notably, we examine poisoning attacks under different proportions of fake users and various popularity conditions to understand why certain deep recommendation models perform exceptionally or sub-optimally. On this basis, we further proposed practical robustness improvement strategy for the problems found in the evaluation and fully verified it through rigorous experiments. Key findings include: (1) the sparser the training dataset, the weaker the robustness of a recommendation model\u2019s performance under adversarial attacks; (2) deep recommendation models exhibit greater robustness in recommending popular items under adversarial attacks, while they are more vulnerable when attacked with non-popular items; (3) the robustness of deep recommendation models is not consistently weaker than that of traditional collaborative filtering models across all attack settings. These findings highlight the security concerns in deep recommendation systems and contribute to developing more reliable models.<\/jats:p>","DOI":"10.1145\/3744570","type":"journal-article","created":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T10:45:34Z","timestamp":1750157134000},"page":"1-46","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Understanding the Robustness of Deep Recommendation under Adversarial Attacks"],"prefix":"10.1145","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3811-6995","authenticated-orcid":false,"given":"Fulan","family":"Qian","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Anhui University, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5254-8502","authenticated-orcid":false,"given":"Wenbin","family":"Chen","sequence":"additional","affiliation":[{"name":"Anhui University, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9479-4005","authenticated-orcid":false,"given":"Hai","family":"Chen","sequence":"additional","affiliation":[{"name":"Anhui University, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-7963-8653","authenticated-orcid":false,"given":"Yan","family":"Cui","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Anhui University, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7647-3603","authenticated-orcid":false,"given":"Shu","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Anhui University, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5678-3038","authenticated-orcid":false,"given":"Yanping","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Anhui University, Hefei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,7]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.11.064"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3347050"},{"key":"e_1_3_2_4_2","unstructured":"Kurakin Alexey. 2016. Adversarial examples in the physical world. arXiv:1607.02533. Retrieved from https:\/\/arxiv.org\/abs\/1607.02533"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462848"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383313.3411447"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4899-7637-6_28"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.12037"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11280-012-0164-6"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3269206.3271743"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115539"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3589000"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/3564284"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539359"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/2020408.2020579"},{"key":"e_1_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/2959100.2959190"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2017.8258235"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.330161"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00040"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00916-8_43"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00140"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3531985"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3366423.3380072"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"e_1_3_2_26_2","unstructured":"C. Gao W. Lei J. Chen S. Wang X. He S. Li B. Li Y. Zhang and P. Jiang. n.\u2009d. CIRS: Bursting filter bubbles by counterfactual interactive recommender system. arXiv:2204.01266. Retrieved from https:\/\/arxiv.org\/abs\/2204.01266"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-39445-5_46"},{"key":"e_1_3_2_28_2","article-title":"A survey on trustworthy recommender systems","author":"Ge Yingqiang","year":"2022","unstructured":"Yingqiang Ge, Shuchang Liu, Zuohui Fu, Juntao Tan, Zelong Li, Shuyuan Xu, Yunqi Li, Yikun Xian, and Yongfeng Zhang. 2022. A survey on trustworthy recommender systems. ACM Transactions on Recommender Systems (2022). arXiv:2207.12515. Retrieved from https:\/\/arxiv.org\/abs\/2207.12515","journal-title":"ACM Transactions on Recommender Systems"},{"key":"e_1_3_2_29_2","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from https:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3583780.3615073"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1145\/2827872"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401063"},{"key":"e_1_3_2_33_2","unstructured":"Xiangnan He Xiaoyu Du Xiang Wang Feng Tian Jinhui Tang and Tat-Seng Chua. 2018. Outer product-based neural collaborative filtering. arXiv:1808.03912. Retrieved from https:\/\/arxiv.org\/abs\/1808.03912"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3209978.3209981"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052569"},{"key":"e_1_3_2_36_2","doi-asserted-by":"crossref","unstructured":"Hai Huang Jiaming Mu Neil Zhenqiang Gong Qi Li Bin Liu and Mingwei Xu. 2021. Data poisoning attacks to deep learning based recommender systems. arXiv:2101.02644. Retrieved from https:\/\/arxiv.org\/abs\/2101.02644","DOI":"10.14722\/ndss.2021.24525"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/2505515.2505665"},{"key":"e_1_3_2_38_2","unstructured":"Zhaohong Jia Hu Zhang Wei Gao Fulan Qian Hai Chen Chunchun Li and Kai Li. 2022. Dual attention recommendation algorithm based on item attributes. Retrieved from https:\/\/www.researchsquare.com\/article\/rs-2206282\/v"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3132847.3132972"},{"key":"e_1_3_2_40_2","first-page":"1885","article-title":"Data poisoning attacks on factorization-based collaborative filtering","volume":"29","author":"Li Bo","year":"2016","unstructured":"Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik. 2016. Data poisoning attacks on factorization-based collaborative filtering. Advances in Neural Information Processing Systems 29 (2016), 1885\u20131893.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_41_2","first-page":"29989","article-title":"Revisiting injective attacks on recommender systems","volume":"35","author":"Li Haoyang","year":"2022","unstructured":"Haoyang Li, Shimin Di, and Lei Chen. 2022. Revisiting injective attacks on recommender systems. Advances in Neural Information Processing Systems 35 (2022), 29989\u201330002.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_42_2","unstructured":"Jiacheng Li Ming Wang Jin Li Jinmiao Fu Xin Shen Jingbo Shang and Julian McAuley. 2023. Text is all you need: Learning language representations for sequential recommendation. arXiv:2305.13731. Retrieved from https:\/\/arxiv.org\/abs\/2305.13731"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/3178876.3186150"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3411884"},{"key":"e_1_3_2_45_2","first-page":"1","article-title":"Shilling black-box recommender systems by learning to generate fake user profiles","author":"Lin Chen","year":"2022","unstructured":"Chen Lin, Si Chen, Meifang Zeng, Sheng Zhang, Min Gao, and Hui Li. 2022. Shilling black-box recommender systems by learning to generate fake user profiles. IEEE Transactions on Neural Networks and Learning Systems (2022), 1\u201315.","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3082317"},{"key":"e_1_3_2_47_2","first-page":"666","volume-title":"Proceedings of the 15th ACM International Conference on Web Search and Data Mining","author":"Ma Wanqi","year":"2022","unstructured":"Wanqi Ma, Xiancong Chen, Weike Pan, and Zhong Ming. 2022. VAE++ variational autoencoder for heterogeneous one-class collaborative filtering. In Proceedings of the 15th ACM International Conference on Web Search and Data Mining, 666\u2013674."},{"key":"e_1_3_2_48_2","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083. Retrieved from https:\/\/arxiv.org\/abs\/1706.06083"},{"key":"e_1_3_2_49_2","first-page":"104329","article-title":"Rflpa: A robust federated learning framework against poisoning attacks with secure aggregation","volume":"37","author":"Mai Peihua","year":"2025","unstructured":"Peihua Mai, Ran Yan, and Yan Pang. 2025. Rflpa: A robust federated learning framework against poisoning attacks with secure aggregation. Advances in Neural Information Processing Systems 37 (2025), 104329\u2013104356.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3567420"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3159652.3159728"},{"key":"e_1_3_2_52_2","first-page":"1","article-title":"Utilizing the influence of multiple potential factors for social recommendation","author":"Qian Fulan","year":"2023","unstructured":"Fulan Qian, Kaili Qin, Hai Chen, Jie Chen, Shu Zhao, Peng Zhou, and Yanping Zhang.2023. Utilizing the influence of multiple potential factors for social recommendation. Knowledge and Information Systems (2023), 1\u201320.","journal-title":"Knowledge and Information Systems"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2023.3248626"},{"key":"e_1_3_2_54_2","unstructured":"Shashank Rajput Nikhil Mehta Anima Singh Raghunandan H. Keshavan Trung Vu Lukasz Heldt Lichan Hong Yi Tay Vinh Q. Tran Jonah Samost et al. 2023. Recommender systems with generative retrieval. arXiv:2305.05065. Retrieved from https:\/\/arxiv.org\/abs\/2305.05065"},{"key":"e_1_3_2_55_2","unstructured":"Ali Shafahi Mahyar Najibi Mohammad Amin Ghiasi Zheng Xu John Dickerson Christoph Studer Larry S. Davis Gavin Taylor and Tom Goldstein. 2019. Adversarial training for free! arXiv:1904.12843. Retrieved from https:\/\/arxiv.org\/abs\/1904.12843"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE48307.2020.00021"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3159652.3159656"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383313.3412243"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1287\/mnsc.1100.1232"},{"key":"e_1_3_2_60_2","first-page":"234","volume-title":"Proceedings of the 17th ACM Conference on Recommender Systems","author":"Wang Changsheng","unstructured":"Changsheng Wang, Jianbai Ye, Wenjie Wang, Chongming Gao, Fuli Feng, and Xiangnan He. Recad: Towards a unified library for recommender attack and defense. In Proceedings of the 17th ACM Conference on Recommender Systems, 234\u2013244."},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30490-4_15"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219869"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/3331184.3331267"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-demo.41"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467335"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3462914"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/2835776.2835837"},{"key":"e_1_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"e_1_3_2_69_2","first-page":"70476","article-title":"Dual defense: Enhancing privacy and mitigating poisoning attacks in federated learning","volume":"37","author":"Xu Runhua","year":"2025","unstructured":"Runhua Xu, Shiqi Gao, Chao Li, James Joshi, and Jianxin Li. 2025. Dual defense: Enhancing privacy and mitigating poisoning attacks in federated learning. Advances in Neural Information Processing Systems 37 (2025), 70476\u201370498.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2840974"},{"key":"e_1_3_2_71_2","first-page":"11987","volume-title":"International Conference on Machine Learning","author":"Yi Mingyang","year":"2021","unstructured":"Mingyang Yi, Lu Hou, Jiacheng Sun, Lifeng Shang, Xin Jiang, Qun Liu, and Zhiming Ma. 2021. Improved ood generalization via adversarial training and pretraining. In International Conference on Machine Learning. PMLR, 11987\u201311997."},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460231.3474275"},{"issue":"5","key":"e_1_3_2_73_2","first-page":"5047","article-title":"LOKI: A practical data poisoning attack framework against next item recommendations","volume":"35","author":"Zhang Hengtong","year":"2022","unstructured":"Hengtong Zhang, Yaliang Li, Bolin Ding, and Jing Gao. 2022. LOKI: A practical data poisoning attack framework against next item recommendations. IEEE Transactions on Knowledge and Data Engineering 35, 5 (2022), 5047\u20135059.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"e_1_3_2_74_2","unstructured":"Kaike Zhang Qi Cao Fei Sun Yunfan Wu Shuchang Tao Huawei Shen and Xueqi Cheng. 2023. Robust recommender system: A survey and future directions. arXiv:2309.02057. Retrieved from https:\/\/arxiv.org\/abs\/2309.02057"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/3640457.3688120"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657684"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1145\/3397271.3401165"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1145\/3132847.3132892"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657814"},{"key":"e_1_3_2_80_2","first-page":"21600","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Zhu Zijian","year":"2023","unstructured":"Zijian Zhu, Yichi Zhang, Hai Chen, Yinpeng Dong, Shu Zhao, Wenbo Ding, Jiachen Zhong, and Shibao Zheng. 2023. Understanding the robustness of 3D object detection with bird\u2019s-eye-view representations in autonomous driving. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 21600\u201321610."}],"container-title":["ACM Transactions on Knowledge Discovery from Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3744570","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,7]],"date-time":"2025-08-07T21:45:50Z","timestamp":1754603150000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3744570"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,7]]},"references-count":79,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2025,8,31]]}},"alternative-id":["10.1145\/3744570"],"URL":"https:\/\/doi.org\/10.1145\/3744570","relation":{},"ISSN":["1556-4681","1556-472X"],"issn-type":[{"type":"print","value":"1556-4681"},{"type":"electronic","value":"1556-472X"}],"subject":[],"published":{"date-parts":[[2025,8,7]]},"assertion":[{"value":"2024-05-23","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-05-28","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-08-07","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}